users consent simple as saml
play

Users' consent - simple as SAML David Simonsen = FED. C FED. - PowerPoint PPT Presentation

Users' consent - simple as SAML David Simonsen = FED. C FED. (USA) FD. FED. r o Kalmar Kalmar FED. Kalmar s s f e d FED. g e e d g e w l d n o w l e K o e K n g e e d w l n o K r FED. a e n g


  1. Users' consent - simple as SAML David Simonsen

  2. =

  3. FED. C FED. (USA) FØD. FED. r o Kalmar Kalmar FED. Kalmar s s f e d FED. g e e d g e w l d n o w l e K o e K n g e e d w l n o K r FED. a e n g e h a g x c a n E c h E x e n g h a x c E t FED. i o FED. n FED. i s FED. c FED. eduGAIN eduGAIN o m FED. i n FED. FED. g

  4. EU directive • Directive 95/46/EC of the . . . l l a European Parliament and of the s u Council of s n 24 October 1995 on the r e protection of individuals with s n o regard to the processing of c t personal data and on the free I movement of such data

  5. Principles • Transparency • Legitimate purpose • Proportionality

  6. Privacy "Privacy is the ability of an individual or group to seclude themselves or information about themselves and thereby reveal themselves selectively ." - WikiPedia

  7. Consent

  8. Purpose What is the service about? • Can the service justify the amount of attributes required ?

  9. Consent • The consent must be • Volentary (no arm-twisting) • Specific (one purpose) • Informed (understandable)

  10. Volentary • 'If you don't consent we will spank you every Monday' Do you consent to sending a personal pseudonym (non-identifiable pointer) to Microsoft?

  11. Specific • 'All connected services may recieve your email- adress' 'BBC may recieve your email-adress'

  12. Informed • 'If you do not consent we will not not decline from not delivering no services' 'If you do not consent you will not get access'

  13. Consent withdrawn • You can always withdraw a consent - but where to do it? Where you gave it... But who did you give it to?

  14. In a Shib-føderation

  15. Central Proxy IdP

  16. Central IdP

  17. Duty of information Consent Consent covers both No personal data should be kept

  18. No personal data is kept 8ds989g+sdfhkjrwk30 ! 2km4756k4l3n43j34j3

  19. Use simpleSAMLphp How to do it?

  20. DEMO TIME

  21. Links • Wiki @ DK-AAI (http://wiki.dk-aai.dk) • Foodle @ FEIDE (http://foodle.feide.no) • DK-AAI website http://www.dk- aai.dk/?do=login • Consent administration @ WAYF https://wayf.wayf.dk/consent/consentAdmin. php

Download Presentation
Download Policy: The content available on the website is offered to you 'AS IS' for your personal information and use only. It cannot be commercialized, licensed, or distributed on other websites without prior consent from the author. To download a presentation, simply click this link. If you encounter any difficulties during the download process, it's possible that the publisher has removed the file from their server.

Recommend


More recommend